Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
References
Configurations
Information
Published : 2020-05-07 09:15
Updated : 2020-05-12 15:15
NVD link : CVE-2020-6652
Mitre link : CVE-2020-6652
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
eaton
- intelligent_power_manager